On July 27, 2026, ShinyHunters claimed it breached EY via a supply chain compromise, setting a leak deadline of July 31. EY's confirmed breach (detected April 23, 2026) involved a third party IT support platform accessed March 28–April 12, exposing client tax info including SSNs and driver's license numbers.

Create a landscape editorial hero image for this Studio Global article: Search & fact-check with cited sources for What did ShinyHunters claim regarding an Ernst & Young breach in July 2026, what deadline did the. Article summary: Here are the findings across all five parts of your question, based on current reporting. ## What ShinyHunters claimed about an EY breach On July 27, 2026, the ShinyHunters extortion gang posted a claim on its dark web l. Topic tags: general, government, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, ch
On July 27, 2026, the prolific data-extortion group ShinyHunters posted a claim on its dark web leak site alleging it had breached Ernst & Young (EY), one of the world's largest professional services firms. The group stated it obtained employee credentials and sensitive files through a supply-chain compromise of a third-party IT support platform used by EY. ShinyHunters issued a "final warning" deadline of July 31, 2026, threatening to release all stolen data and files if EY did not negotiate before that date. The leak-site notice, updated on July 27, read: "This is a final warning to reach out by 31 July 2026 before we leak along with selling the data to the highest bidder."
Analysts are treating the claim with skepticism for several reasons:
Before ShinyHunters' claim, EY had already disclosed a separate, confirmed data breach involving a third-party IT service management (ITSM) platform used for internal support tickets. Key details:
The confirmed third-party breach and the ShinyHunters claim are not the same incident — the former is a documented event EY disclosed; the latter is an unsubstantiated claim that may or may not be connected.
ShinyHunters has been one of the most prolific data-theft and extortion groups of 2026, operating a consistent "breach, exfiltrate, demand, and publish-or-sell" model. Major 2026 campaigns include:
The group's tradecraft relies on voice phishing (vishing), credential theft, OAuth token abuse, and supply-chain compromise rather than encryption-based ransomware. Analysts also note that ShinyHunters has re-extorted victims after payment — most notably in the PowerSchool case — making negotiation a risky strategy.
The FBI, Mandiant, and EclecticIQ have all issued advisories tracking ShinyHunters as a financially motivated, extortion-as-a-service collective that has expanded rapidly through AI-enabled social engineering and SaaS platform exploitation.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
On July 27, 2026, ShinyHunters claimed it breached EY via a supply chain compromise, setting a leak deadline of July 31.
On July 27, 2026, ShinyHunters claimed it breached EY via a supply chain compromise, setting a leak deadline of July 31. EY's confirmed breach (detected April 23, 2026) involved a third party IT support platform accessed March 28–April 12, exposing client tax info including SSNs and driver's license numbers.